MEDIUM
GHSA-pxmp-fwjc-4x7q
HTML Injection in marky-markdown
Details
All versions of `marky-markdown` are vulnerable to HTML Injection due to a validation bypass. The package only allows iframes where the source is `youtube.com` but it is possible to bypass the validation with sources where `youtube.com` is the sub-domain, such as `youtube.com.evil.co`. This
## Recommendation
This package is no longer maintained. Please upgrade to `@npmcorp/marky-markdown`
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/marky-markdown
Introduced in:
0.0.0No fixed version published yet for marky-markdown (npm). Pin to a known-safe version or switch to an alternative.